Commit Graph

3760 Commits

Author SHA1 Message Date
r-vdp
86a665d5b6 nixos/etc-overlay: fix machine-id-commit on first-boot when /etc is RO
The upstream unit has ConditionPathIsReadWrite=/etc, which is always
false on the read-only overlay, so the previous commit alone requires
users that want persistence to override the conditions themselves before
the generated ID can be written back.

Use ConditionFirstBoot instead, with the empty placeholder
first-boot is "no" and commit stays skipped, but when a writable
file containing "uninitialized" is bind-mounted over /etc/machine-id,
first-boot is "yes" once and commit writes the ID through the bind.
2026-06-26 10:50:58 +02:00
r-vdp
3eaafe4d48 nixos/etc-overlay: ship empty /etc/machine-id on immutable /etc
The symlink to /var/lib/nixos/machine-id never persists the ID,
systemd-machine-id-commit.service requires a writable /etc, and
machine_id_commit() does not follow symlinks for its mountpoint check.
So the backing file stays "uninitialized", every boot is
ConditionFirstBoot=yes, and the machine-id is random per boot.

Ship an empty regular file instead, systemd then overlays /run/machine-id
for the session, ConditionFirstBoot is correctly "no", commit is
cleanly condition-skipped, and the file is a usable bind target for
users that want persistence.

Fixes #523878
2026-06-26 10:50:57 +02:00
r-vdp
5640e1f935 nixos/limine: add extraInstallCommands option
Allows running additional shell commands after the limine install script
generates menu entries, mirroring the systemd-boot option of the same
name.

Co-authored-by: Florian Klink <flokli@flokli.de>
2026-06-25 22:58:22 +02:00
nixpkgs-ci[bot]
68cd6bba16 Merge master into staging-nixos 2026-06-25 18:47:24 +00:00
nixpkgs-ci[bot]
42814ad4b8 Merge master into staging-next 2026-06-25 18:46:06 +00:00
Arian van Putten
37d4094e73 nixos/systemd/tmpfiles: add credstore.conf (#534998) 2026-06-25 16:23:49 +00:00
Florian Klink
d406556640 nixos/journald-{gateway,remote}: remove TLS support (#535263) 2026-06-25 16:12:50 +00:00
Arian van Putten
921383b2ce nixos/journald-{gateway,remote}: remove TLS support
We aren't linking systemd to gnutls anymore so these options
were all silently ignored. Which is pretty bad!

Assisted-by: Claude <noreply@anthropic.com>
2026-06-25 15:47:45 +02:00
Florian Klink
68439b2129 nixos/etc: inline small regular files into the etc-overlay metadata image (#510323) 2026-06-25 13:20:50 +00:00
Arian van Putten
3d47d8331a nixos/systemd: add many Varlink APIs since v260 (#533730) 2026-06-25 08:06:37 +00:00
Raito Bezarius
588eb06fcc nixos/systemd/tpm2/pcrextend: add Varlink API
This adds io.systemd.PCRExtend if the system has TPM2
enabled.

Additionally, this requires the system to fullfill
ConditionSecurity=measured-uki.

Change-Id: I3f1046cdc7463f3b6d3205030f7f12ac95e5cd9e
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:39 +02:00
Raito Bezarius
13684b8470 nixos/systemd/resolved: add Varlink APIs
This adds:

- /run/systemd/resolve/io.systemd.Resolve (resolution)
- /run/systemd/resolve/io.systemd.Resolve.Monitor (monitoring)

Change-Id: I43f22be5c42757f3dad1e4a9d209b0a91f404a55
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
5c6a1e2b3d nixos/systemd/udevd: add Varlink API
This adds io.systemd.Udev by default.

Change-Id: I41fec3831049aec03041a9ac8a282088e1773b79
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
04f7553ac2 nixos/systemd/networkd: add Varlink APIs
This adds:

- /run/systemd/resolve.hook/io.systemd.Network (DNS hook)
- /run/systemd/report/io.systemd.Network (metrics)
- /run/systemd/netif/io.systemd.Network (management)

Change-Id: I3d63b0723ae5f8f9496418d8f5d857809302155e
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
b8b65f1616 nixos/systemd/factory-reset: add Varlink API
This adds io.systemd.FactoryReset by default.

Change-Id: I2ef8ae8812e76bc81a5f962e9bfeb99967f6df83
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
65cdcfc133 nixos/systemd/mute-console: add Varlink API
This adds io.systemd.MuteConsole by default.

Change-Id: I613d5f12e5b2742206c3023e4d57ccdfbaf0e704
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
ff55fdd003 nixos/systemd/machined: add Varlink API
This adds io.systemd.Machine by default.

Change-Id: I05e595d22ad06504e2b3aacb48c74e7683057ce3
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
3003651b5a nixos/systemd/importd: add Varlink API
This adds io.systemd.Import by default.

Change-Id: Idad216f83af2f3402b864a162373f04968725b7b
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
7dacd14feb nixos/systemd/ask-password: add Varlink API
This adds io.systemd.AskPassword Varlink API by default.

Change-Id: I45b9a53d489ec3ea5561006c9c91ccb7016b3ee1
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
Raito Bezarius
1fc433dc51 nixos/systemd/repart: add Varlink socket
This enables the ability to use systemd-repart over Varlink at
/run/systemd/io.systemd.Repart.

Change-Id: Ia74fdf8c2cbc4ec52994ba8ceb5796acc731abd3
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-25 09:50:38 +02:00
nixpkgs-ci[bot]
a3eab19ade Merge master into staging-nixos 2026-06-25 00:46:31 +00:00
nixpkgs-ci[bot]
7ac2687f5f Merge master into staging-next 2026-06-25 00:45:19 +00:00
Raito Bezarius
6a63a4ad8b pkgs/*: drop maintenanceship of various packages
I have effectively renounced on maintaining all these packages and I do
not plan to return them except if I'm forced to.

I am also fine with most of these packages being dropped for next
releases if no maintainer shows up.

Change-Id: I8d167c8029b6991181bd7a094af21c3313af2b51
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2026-06-24 20:34:45 +02:00
Arian van Putten
8651ab7d4d nixos/systemd/tmpfiles: add credstore.conf
This creates the /{etc,run}/credstore{,.encrypted} directories
from which ImportCredential= picks up credentials
2026-06-24 18:20:31 +02:00
Vladimír Čunát
105327541b Reapply "staging-nixos merge for 2026-06-19" (#534864)
This reverts commit 532f984da0, reversing
changes made to 421ceaeef8.
2026-06-24 12:17:06 +02:00
Vladimír Čunát
a6c3b1d396 Merge master into staging-nixos 2026-06-24 12:16:37 +02:00
Vladimír Čunát
6e628a4f79 Revert "staging-nixos merge for 2026-06-19" 2026-06-24 10:55:53 +02:00
nixpkgs-ci[bot]
5c3bf48741 Merge master into staging-nixos 2026-06-23 12:59:56 +00:00
nikstur
efd34ae45a nixos/uki: use config systemd package (#530536) 2026-06-23 12:36:04 +00:00
r-vdp
b3a73f17ba nixos/limine: format the install script 2026-06-22 16:21:35 +02:00
Will Fancher
d54bf2afa2 nixos/systemd-initrd: add systemd.*.services.path to initrd store (#462515) 2026-06-20 03:42:37 +00:00
Will Fancher
f446ff996a nixos/luksroot: Clarify preLVM with systemd stage 1 (#532037) 2026-06-19 22:23:42 +00:00
nixpkgs-ci[bot]
b0682b66df Merge master into staging-nixos 2026-06-17 07:53:25 +00:00
Ramses
16122d6bd9 nixos/systemd-initrd: skip activation when init= is not a NixOS system (#532008) 2026-06-17 07:25:15 +00:00
Masum Reza
0c505d8bfa nixos/limine: fix secure boot key generation when using impermanence (#514762) 2026-06-17 04:57:48 +00:00
coolcuber
044b1b8fea nixos/plymouth: add showDelay option 2026-06-16 19:38:34 -04:00
Ilan Joselevich
f61ff68f63 nixos-init: skip the etc overlay for a non-NixOS init=
find-etc verified the init= was inside a NixOS toplevel and bailed otherwise,
failing initrd-find-etc.service. The etc-overlay mounts require it, so for a
non-NixOS init= (e.g. init=/bin/sh) the initrd dropped to emergency mode before
initrd-init could switch-root into the target.

Make find-etc skip silently for a non-NixOS init=, leaving the /etc-basedir and
/etc-metadata-image symlinks uncreated, and gate the etc-metadata mount, the
/sysroot/etc overlay and the rw-etc service on those symlinks with
ConditionPathExists so they skip instead of fail. initrd-init then switch-roots
into the non-NixOS init directly. The NixOS path is unchanged: the symlinks
exist, so the conditions hold.

Extend the systemd-initrd-non-nixos test with a second node enabling
system.nixos-init.enable, so both the bash initrd-nixos-activation path and the
nixos-init path are covered.

Assisted-by: Claude:claude-opus-4-8
2026-06-16 17:32:17 +03:00
Oskar Philipsson
2e23af70a8 nixos/systemd-initrd: add systemd.*.services.path to initrd store 2026-06-16 01:15:07 +02:00
Adam C. Stephens
bed020fc90 nixos/tzpfms: init (#517991) 2026-06-15 18:03:18 +00:00
Will Fancher
1bd486a330 nixos/luksroot: Clarify preLVM with systemd stage 1 2026-06-15 13:33:13 -04:00
Ilan Joselevich
feaf19ea26 nixos/systemd-initrd: skip activation when init= is not a NixOS system
initrd-nixos-activation ran the closure's prepare-root unconditionally. For a
non-NixOS init= there is no prepare-root, so the service failed, and since
initrd-switch-root.service requires it, switch-root never ran and the machine
dropped to the emergency shell. This broke init=/bin/sh recovery, and microVMs
that serve /nix/store over virtiofs and boot an arbitrary binary as init=.

initrd-find-nixos-closure already detects this and writes a non-empty NEW_INIT
to /etc/switch-root.conf (empty for a NixOS init). Read it via the same
EnvironmentFile= initrd-switch-root uses and skip activation when it's set, so
a non-NixOS init= switch-roots into its target directly. The NixOS path is
unchanged.

Also add a test booting a non-NixOS init=. It uses a store path rather than
/bin/sh: a real root already has /bin/sh and an os-release, but a fresh test
root has neither, so the test uses a tmpfs root and writes os-release first.

Assisted-by: Claude:claude-opus-4-8
2026-06-15 19:28:19 +03:00
K900
1fdf8fd586 bootspec: honor boot.kernel.enable
WSL and other container-brained-but-not-really systems may not want a kernel,
and now that bootspec is no longer optional, this pulls one in anyway.
2026-06-11 15:38:11 +03:00
Josh Hoffer
140489168e nixos/uki: use config systemd package
Use the config's systemd package. This makes patching systemd-stub
easier. All other ukify settings are set from config so this is
more consistent.
2026-06-10 15:48:19 -07:00
Arian van Putten
f9335936bc nixos/bootspec: remove enable option (#530066) 2026-06-10 19:34:34 +00:00
Alyssa Ross
2d18606282 lib/systems: move kernel configuration out of the platform structure (#530133) 2026-06-10 17:39:49 +00:00
·𐑑𐑴𐑕𐑑𐑩𐑤
a7be344fe7 nixos/system/boot/tzpfms: init 2026-06-10 15:42:38 +07:00
Emily
31d1d80b3f lib/systems: move kernel configuration out of the platform structure
Currently, you need to override `stdenv.hostPlatform` to request a
compressed kernel on AArch64, and the kernel configuration is split
between the central structured configuration and string snippets in
platform definitions. This has consequently made the latter bitrot
terribly. Since the platform‐specific logic is now very limited after
cleaning up the detritus, we can move it into the kernel derivation
and expose the relevant configuration there for anyone who wants to
customize it further or needs to read it out.

Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2026-06-10 11:17:38 +10:00
r-vdp
dff88cbd79 nixos/systemd-boot: drop bootspec synthesize fallback
Older generations without boot.json are skipped with a
warning.
2026-06-09 22:03:07 +03:00
r-vdp
c44bf2a69d nixos/bootspec: remove enable option
Bootspec has been enabled by default and marked internal for a long
time.

Dropping this option avoids us needing fallbacks in bootloader scripts.
2026-06-09 21:45:54 +03:00
Masum Reza
4b59bc72ab nixos/limine: fix fwupd-efi signing script under strict shell checks (#526918) 2026-06-09 16:37:53 +00:00